UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
ID: a426a8c9-d409-502d-aefe-f98a4c0a9d32
STIX ID: report--a426a8c9-d409-502d-aefe-f98a4c0a9d32
Feed Name: The Hacker News
**UAT-10147 campaign**: Researchers attribute a large-scale, Chinese-speaking cybercrime campaign to UAT-10147 that uses publicly disclosed vulnerabilities and AI-assisted tooling to compromise Windows and Linux web servers across multiple sectors and countries, deploy web shells and implants (BadIIS, Quasar RAT, Gh0stCringe, Noodle RAT) and a new cross-platform backdoor called SPECTRE which includes kernel-level rootkit and EDR-bypass capabilities, enabling persistent data theft and SEO fraud from an exposed target list of roughly 170,000 URLs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
